Live data from Hacker News

The "email is authentication" pattern

rubenerd.com

191–200 of 474 posts

Re: The "email is authentication" pattern

#191
post #15

Earlier quoted context omitted.

Who copy and pastes from a password manager? Here’s my workflow, and I consider it superior to both of the above. Go to site, Safari offers to autofill, give TouchID/FaceID, get asked for a 2 factor code. Sent via SMS/email? Safari offers to autofill for me. TOTP style? Safari offers to autofill for me. Easy peasy. Passkeys are even easier as there is no second step and waiting for SMS/email.

> Who copy and pastes from a password manager? I do! And way more than I would like, because for some reason it's "modern" to have a login flow that first requests your email, and then you have to click next for it to request your password... Not even gonna go into detail about all the other cases like websites that have such bad field identification that the password manager has no clue where to put the username/ema…

Keepassxc's desktop browser extension allows you to specify the username and password boxes. Even if they are on separate pages. It's really a painless 15 second process.

I have to do it on my bank's website every few months.

Re: The "email is authentication" pattern

#192
post #3

Email accounts are the highest common denominator in online authentication. Phones are competitive, but people lose phones. Phone numbers are more common and durable, but the security of phone numbers is leagues below that of a flagship provider email account. It makes sense that so many authentication flows work this way. When designing a "fantasy football" alternate authentication system for the Internet, start wit…

Government provided digital IDs would solve a lot of this. Yes, they may have their own problems, but outsourcing the action of identifying individuals to the government seems valuable and less prone to "lock outs" like Google and friends.

Estonia has this: https://e-estonia.com/solutions/estonian-e-identity/id-card/>

Finland tried to copy it, but the Finnish card (while based on the same technology) is used very little. Finnish banks already had their own OTP solutions, which they started offering for authentication on other web sites, so no-one wanted an extra authenticator on top of that. This of course means that you get phishing emails pretending to be from all sorts of government services, where the goal is to get your banking credentials and take your money.

Since then, mobile phone operators added their own authentication system based on credentials residing on your SIM card https://mobiilivarmenne.fi/en/>. You prove your identity when getting a mobile phone contract and can then use that to log into many sites.

Re: The "email is authentication" pattern

#193

Earlier quoted context omitted.

Government provided digital IDs would solve a lot of this. Yes, they may have their own problems, but outsourcing the action of identifying individuals to the government seems valuable and less prone to "lock outs" like Google and friends.

I think I've said it before, but I want USPS-provided email. To set one up you'd go to a post office, verify your identity in some way, and set up an email. If you forget your password and want to recover it, you'd have to go back into a post office and verify your identity again.

I’m not sure I trust USPS to get all of the ins/outs of email spam/security/ux right. Google has spent a lot of resources to get Gmail to where it is today, starting from scratch (or OSS) seems like a big ask.

Maybe we just ask for an open authentication system instead? Leave the email part to someone else… and maybe the open authentication can plug a crypto app/email/phone backend for recovery once it is setup. Heck, given that’s it’s the USPS, they will probably offer a snail-mail recovery option (for better or worse.)

Re: The "email is authentication" pattern

#194

Earlier quoted context omitted.

How about a bank-provided digital id that you get when opening an account by walking into a physical bank location and providing your photo ID? It would tick the "less prone to lock out" problem without placing even more power in government hands.

We have this in Belgium and it’s really not that good. It created a pattern of companies relying on people having an account at certain banks; which when you’re either immigrant or unbanked is unlikely and shuts you out of certain businesses. It’s been phased out for the government provided login system which is much better but not exactly simple for laypeople to set up. On top of this, integrating with it requires a…

Banking credentials are used a lot in Finland to sign into other services. This means you get phishing emails saying "your medical test results are available" or "you're getting a tax return" where the actual goal is to get into your bank account.

Re: The "email is authentication" pattern

#195

Earlier quoted context omitted.

To get a RealID drivers license in the US, which will be required to board a plane soon, requires all of the above and more. It’s a government in-person KYC.

The irony with that is that if someone undocumented wanted to leave the country, this requirement could potentially hinder that. I also don't really want to have to carry my green card around everywhere. Just one more thing that can be lost.

How would it?

To travel internationally, a passport is required (not drivers licenses).

Re: The "email is authentication" pattern

#196
post #139
post #120

Earlier quoted context omitted.

> If the answer is "they just don't get access anymore" or "a panel of their peers attests to them", your fantasy authentication system also needs a fantasy species of sentient beings to serve as users, because it won't work for humans. This has been my single biggest argument against blockchain/cryptocurrency stuff for years: the "lose your key, lose your wallet" thing is fundamentally incompatible with real users.…

I don't know, we carried physical money for millenia. Humans managed that.

Yeah and it sucked which is why we invented better solutions.

What most bitcoin fans seem not to understand is that for the vast majority of people, transactions being reversible by authority figures is desirable.

Re: The "email is authentication" pattern

#197
post #139

Earlier quoted context omitted.

I don't know, we carried physical money for millenia. Humans managed that.

Money occupies physical space, so for most of history there was a pretty low cap on how much you could bring with you at once, which placed a cap on how much a single mistake could cost you.

That cap has always and still does exceed the median worth.

Re: The "email is authentication" pattern

#198

Earlier quoted context omitted.

No it isn’t. No more than a wallet key. If I lose $1 note. It’s gone. If I recover it, then it’s no longer lost.

A $1 note being a macro scale physical object enjoys a variety of benefits such as object permanence which provide a baseline level of recoverability. Whereas a wallet key l, being a number, enjoys no such protections. Of course you may choose to encode your wallet key on paper, metal, or stone granting it properties not unlike a note. However you have now compromised the security of your wallet as well it becomes no…

You can encode your bitcoin in wallets of predetermined size, spreading your risk.

But you’re reinventing money with extra steps.

Re: The "email is authentication" pattern

#199
Disclaimer: I loathe this pattern & hope something like WebAuthn prevails instead.

That said, if folks are going to adopt this as a primary flow, perhaps email clients need to build in support. For OS providers like Apple, maybe this means less emphasis on the easy Passkey method and more on fixing the finicky email login flow that sites use instead?

What would a good email login flow look like? What is the "password manager" equivalent in a magic link world? On something like iOS or MacOS with Safari, could the browser/app & email client communicate to make the login seamless (after the email delay)?

Are new OS-level APIs needed for native apps such that they don't require switching apps to login? (This is a truly awful workflow.)

Should sites stop making people register with passwords at all? What is the point of passwords when auth is primarily handled through magic links?

Re: The "email is authentication" pattern

#200
post #107

Earlier quoted context omitted.

I think I've said it before, but I want USPS-provided email. To set one up you'd go to a post office, verify your identity in some way, and set up an email. If you forget your password and want to recover it, you'd have to go back into a post office and verify your identity again.

Germany has PostIdent: you are issued a code, take it to the closest post office, hand them the code (originally this involved printouts) and your ID card and they scan your ID card and enter it into their system where the issuer of the code can then request that info to verify your identity. This has largely been replaced by videochat for ID card verification where some underpaid person walks you through holding you…

https://en.wikipedia.org/wiki/De-Mail also was an attempt
Post reply on HN